paper-with-me

Papers

Discrete optimal transport is a strong audio adversarial attack

2025-09-18 · Anton Selitskiy, Akib Shahriyar, Jishnuraj Prakasan arxiv

In this paper, we investigate discrete optimal transport (DOT) as a black-box attack against modern automatic speaker verification (ASV) and anti-spoofing countermeasure (CM) systems. Our attack operates as a post-processing distribution-alignment step. Frame-level WavLM embeddings of generated speech (or another person speech) are aligned to an unpaired bona fide speech pool using entropic optimal transport and a top-k barycentric projection, followed by neural vocoding. Unlike gradient-based attacks, the proposed method requires no access to model parameters, gradients, or training data. Experiments on ASVspoof2019 and ASVspoof5 demonstrate that DOT attack substantially increases CM EER and substantially degrades ASV performance across multiple spoofing attacks. The attack transfers across datasets and remains effective after CM fine-tuning. Analysis using speaker similarity, Fréchet Audio Distance, and visualization of embedding distributions suggests that DOT succeeds by shifting source speech toward bona fide regions of the representation space rather than by maximizing speaker similarity. These results indicate that optimal-transport-based distribution alignment represents a previously underexplored attack vector for contemporary ASV and anti-spoofing systems.

📄 PDF Abstract BibTeX arXiv:2509.14959

Code (0)

등록된 구현이 없습니다.

Tasks

Speaker VerificationAdversarial Attack

Similar Papers 제목 키워드 기반

Discrete Optimal Transport and Voice Conversion

2025-05-07 · Anton Selitskiy, Maitreya Kocharekar

In this work, we address the voice conversion (VC) task using a vector-based interface. To align audio embeddings between speakers, we employ discrete optimal transport mapping. Our evaluation results demonstrate the hig…

Audio GenerationVoice Conversion

k-GANs: Ensemble of Generative Models with Semi-Discrete Optimal Transport

2019-07-09 · Luca Ambrogioni, Umut Güçlü, Marcel van Gerven

Generative adversarial networks (GANs) are the state of the art in generative modeling. Unfortunately, most GAN methods are susceptible to mode collapse, meaning that they tend to capture only a subset of the modes of th…

Semidiscrete optimal transport with unknown costs

2023-10-01 · Yinchu Zhu, Ilya O. Ryzhov

Semidiscrete optimal transport is a challenging generalization of the classical transportation problem in linear programming. The goal is to design a joint distribution for two random variables (one continuous, one discr…

On the Existence of Optimal Transport Gradient for Learning Generative Models

2021-02-10 · Antoine Houdard, Arthur Leclaire, Nicolas Papadakis, Julien Rabin

The use of optimal transport cost for learning generative models has become popular with Wasserstein Generative Adversarial Networks (WGAN). Training of WGAN relies on a theoretical background: the calculation of the gra…

valid

Connecting adversarial attacks and optimal transport for domain adaptation

2022-05-30 · Arip Asadulaev, Vitaly Shutov, Alexander Korotin, Alexander Panfilov 외

We present a novel algorithm for domain adaptation using optimal transport. In domain adaptation, the goal is to adapt a classifier trained on the source domain samples to the target domain. In our method, we use optimal…

Domain Adaptation